Data processing agreement (DPA)
Last updated: 2026-06-12 · Draft to be reviewed by a lawyer before signature
1. Purpose
This agreement governs the personal data processing performed by the tool on behalf of the customer for the AI visibility service: site scans, file generation, citation tracking.
2. Roles
The customer is the data controller. The tool publisher acts as a processor under article 28 GDPR, on the customer's documented instructions.
3. Sub-processors
Hosting and database in the European Union (Supabase, EU project; Upstash, EU region). Payments by Stripe. Text generation by Anthropic and Mistral AI: only public information from the scanned site is sent to them, never account data. The up-to-date list is available on request.
4. Security
Encryption in transit, per-account isolation (row level security), API keys stored server side, minimisation: only the data needed for the service is kept.
5. Duration and return
Data is kept for the duration of the contract. On termination or request it is deleted: account deletion erases sites, scans, generated files and measures.
6. Assistance and rights
The publisher assists the customer with data subject requests (access, erasure, portability) through the built-in export and deletion functions, or by email.